IronWall Cyber Solutions IRONWALL CYBER SOLUTIONS ← Back to Resources
← Back to Resources
Best Practices

Email Spoofing: Why "From" Lies — and How SPF, DKIM & DMARC Fix It

Published May 25, 2026 6 min read

Email spoofing is the forging of the "From" address on a message so that it appears to come from a domain the sender does not actually control. The defence is three email-authentication records — SPF, DKIM and DMARC — which are free, live in your domain settings, and once configured quietly stop most impersonation of your name.

Here is the uncomfortable part: by default, the "From" address on an email is about as trustworthy as the return address written on a physical envelope. Anyone can write anything there. That is how attackers send messages that appear to come from your company — to your customers, your staff, even your own finance team.

SPF Lists which servers are allowed to send mail for your domain
DKIM Adds a tamper-proof signature proving the mail is genuine
DMARC Tells receivers what to do with mail that fails — and reports back
The three records work together: SPF and DKIM authenticate, DMARC enforces and reports.

This has a name and a number. The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025, totalling $3,046,598,558. That is the crime where an invoice arrives from a supplier who did not send it. Email authentication is the cheapest defence against the version that pretends to be you.

Figure verified 31 July 2026. Source linked above.

Why is the "From" address so easy to fake?

Because email was designed for a smaller, more trusting network, and the address you see at the top of a message is simply a text field the sending software fills in. Nothing in the original design requires the sender to prove that the name belongs to them, and for decades receiving servers accepted whatever they were told.

That matters more than it first appears, because the target is rarely your own systems. Your mailbox is untouched. What gets used is your reputation: a message that looks like your invoice, sent to a customer with different bank details on it, or a note that looks like it came from you asking a member of staff to move money quickly. The recipient has no obvious way to tell the difference. Email authentication closes that gap by giving the receiving server something it can independently verify before the message ever reaches an inbox.

What do SPF, DKIM and DMARC each do?

SPF — who is allowed to send

SPF, or Sender Policy Framework, is a public list of the mail servers permitted to send email for your domain. A receiving server checks that list, and a message arriving from a server that is not on it is treated as suspicious.

DKIM — proof it was not tampered with

DKIM, or DomainKeys Identified Mail, adds a cryptographic signature to your outgoing mail. The receiver verifies that signature against a public key published in your domain, which confirms both that the message genuinely came from you and that nobody altered it along the way.

DMARC — the enforcement policy

DMARC ties the first two together and tells receiving servers what to do when a message fails: nothing, quarantine it into the spam folder, or reject it outright. It also sends you reports showing who has been sending mail under your name.

SPF and DKIM answer the question "is this really you?" DMARC decides what happens when the answer is no.

How do you roll it out without breaking legitimate email?

Carefully, and in order. The risk here is not the attacker — it is switching on enforcement before you have accounted for every service that sends mail on your behalf, and quietly blocking your own invoices. The stages below avoid that.

  • Publish SPF and DKIM first. Make sure every legitimate sender is included: your email host, your marketing platform, your invoicing or accounting software, and anything else that puts your domain in the "From" line.
  • Start DMARC in monitor mode. This collects reports without affecting delivery at all, so nothing your business sends is at risk while you are still learning what is out there.
  • Read the reports before you change anything. Confirm that your real mail is passing and identify any sender you missed. This is the step people skip, and the one that prevents the problem.
  • Tighten to quarantine, then to reject. Move one step at a time, once the reports are clean. This is the point at which impersonation is actually blocked.

Which senders do businesses usually forget?

The ones nobody thinks of as email. Most failed rollouts trace back to a legitimate service that was never added to the records, so it is worth walking this list before you tighten anything.

Sender Why it gets missed What it needs
Your email host Rarely missed, but often the only sender anyone remembers to add SPF entry plus DKIM signing enabled in the admin console
Marketing and newsletter tools Often set up by a different person, years earlier, and never revisited Its own SPF entry and DKIM keys published in your domain
Invoicing and accounting software Sends under your name but feels like finance, not email Authentication configured before enforcement, or invoices start failing
Website forms and booking systems Automated confirmations nobody considers "mail we send" Either proper authentication, or a sending address you do control
Helpdesk and support platforms Replies go out under your domain from a third-party system Vendor-supplied records added before you move past monitor mode

The bottom line

SPF, DKIM and DMARC cost nothing but a little setup time. They protect your name, give you visibility into who is sending mail as you, and stop a whole category of phishing that borrows the trust your customers place in you.

Stopping domain impersonation

1
1. By default, anyone can forge your "From"
2
2. SPF lists your authorized sending servers
3
3. DKIM signs mail to prove it is genuine
4
4. DMARC blocks or quarantines forgeries
5
5. DMARC reports show who is spoofing you
6
6. Legitimate mail lands; impersonation fails

See where you actually stand

A QuickScan gives you a clear external risk score, a letter grade, and your top fixes in 48 hours. No passwords, no agents, no internal access — and it is not a penetration test.

See QuickScan options — from $349

Rather pick a time first? Book your QuickScan intake and your secure payment link follows automatically.